Privacy Policy

Last updated: April 10, 2026 | Version 1.0

1. What Data We Collect

Iris.Art collects biometric data including iris images, voice recordings, pulse signals, facial photographs, and handwriting samples. This data is classified as "special category" personal data under GDPR Article 9 and "sensitive personal information" under CCPA/CPRA.

2. How We Use Your Data

We process your biometric data solely to extract interpretable features and generate personalized music compositions. We do not use your data for identification, surveillance, health diagnostics, or any purpose other than art generation.

3. Data Storage & Encryption

Raw biometric data is encrypted at rest using AES-256-GCM with per-record initialization vectors. Encrypted data is stored in Supabase Storage. Feature vectors and embeddings are stored in our database with row-level security policies that restrict access to the data owner.

4. Third Parties

The following third parties process your data:

5. Your Rights

You have the right to:

6. Data Retention

Your data is retained until you request deletion or until 3 years after your last activity, whichever comes first. Compositions and report cards are retained independently of raw biometric data.

7. Do Not Sell or Share

We do not sell, share, or disclose your personal information to third parties for purposes other than those described in this policy. Under CCPA/CPRA, you have the right to opt out of the sale or sharing of your personal information. Since we do not sell or share data, this right is automatically satisfied.

8. Geographic Restrictions

Iris.Art is not available to residents of Illinois, United States, due to the Illinois Biometric Information Privacy Act (BIPA).

9. Contact

For privacy inquiries, data deletion requests, or to exercise your rights, contact us at: privacy@iris.art